Nigeria Policy Placement Audit
Version: v1 third-pass draft Research date: 2026-06-18 Status: Practical product/compliance placement audit, not legal advice
This audit records where Nigeria legal and policy notices are surfaced in product flows after the second pass. Nigerian counsel must still review the policy text, acceptance language, regulator references, and launch gates before public launch.
Research Basis
- NDPC/GAID materials emphasize conspicuous homepage privacy and cookie notices, accept/decline choices for non-essential cookies, and accountable consent records.
- FCCPC e-commerce materials emphasize clear terms, restrictions, cancellation windows, return/refund handling, prompt redress, and privacy protection.
- CBN/CDD/AML materials emphasize customer identification, KYC/KYB, risk-based monitoring, transaction controls, suspicious activity handling, and provider readiness for regulated payment flows.
- NPF-NCCC materials provide an official Nigerian cybercrime reporting route for fraud and online safety escalation.
See SOURCES.md for the source URLs and legal-review caveats.
Public Web Placements
- Global access:
Layoutfooter and user menu link to the Nigeria policy center, Privacy, Terms, Support, Safety, Trust Passport, and wallet sections where applicable. - Homepage: a centered privacy/cookie notice appears for unauthenticated visitors with accept notice and decline non-essential cookies actions. This keeps the notice visible without enabling non-essential tracking.
- Authentication: signup and login continue to link Terms, Privacy, and Trust Passport rules at account creation/sign-in.
- Verification: phone, email, selfie, and identity verification now link Privacy, Trust Passport, AML/KYC and Fraud, and retention/law-enforcement policies where personal identity or trust eligibility data is submitted.
- Settings and privacy controls: privacy settings, data export, and account deletion now link Privacy and retention policies, including reminders that safety, fraud, finance, and legal records may be retained.
- Support and reports: support ticket creation and the report center now link refunds/disputes, safety, AML/KYC and fraud, acceptable use, copyright, and retention policies depending on the report context.
- Safety Sessions: eligibility, emergency actions, and start confirmation now link Safety, Privacy, and retention policies for location, trusted contact, check-in, escalation, and evidence handling.
- Payments and checkout: payment detail, dispute, checkout link, public checkout landing, and checkout status now link Wallet and Payments, Refund Policy, AML/KYC and Fraud, and Data Retention Policy.
- Marketplace and seller surfaces: listing creation, listing detail, order detail, seller center, buyer offers, delivery proof, and disputes now link Seller Policy, Acceptable Use, Content/Copyright, Event Policy where relevant, Wallet and Payments, Refund Policy, AML/KYC and Fraud, Safety, Trust Passport, and Data Retention policies. The wording preserves the paused checkout/escrow scope.
- Events and communities: community creation and event surfaces should link Community Guidelines, Event Policy, Refund Policy, Safety, Trust Passport, Privacy, and Data Retention Policy where organizer/attendee data, payment, QR, safety, or cancellation rules apply.
- Community creation: creator-facing community setup now links Community Guidelines, Acceptable Use, and Content/Copyright policies.
iOS Placements
- Auth: login and registration show Terms, Privacy, and Trust Passport links.
- Settings: privacy, data export, and account deletion panels show Privacy and retention links.
- Trust: verification panels show Trust Passport, Privacy, and AML/KYC and Fraud links.
- Payments: wallet transfer, payment request, payment dispute, and orders show Wallet and Payments, Refunds and Disputes, AML/KYC and Fraud, and retention links.
- Marketplace: marketplace hub, listing draft, listing detail, offer/purchase options, group buys, and order proof/dispute flows show acceptable use, copyright, paid activity, wallet/payment, refund/dispute, retention, and safety links while keeping marketplace money flows paused.
- Safety/support/report: safety session, support ticket, and report issue screens show Safety, Privacy, retention, refunds/disputes, AML/KYC and Fraud, acceptable use, and copyright links.
Remaining Counsel/Product Blockers
- Nigerian counsel must confirm final NDPA/NDPC/GAID wording, cookie consent implementation, DPCMI registration/audit duties, breach notification duties, cross-border transfer language, and exact data subject request timelines.
- Payment counsel/provider review must confirm whether ZenWave is only a technical facilitator or becomes a regulated payment, wallet, escrow, stored-value, lending, or marketplace payment actor under CBN rules.
- Marketplace checkout, escrow, wallet funding, broad group-buy money flows, payouts, and installment checkout should remain paused until provider contracts, AML/KYC, fraud monitoring, refunds, dispute handling, ledger reconciliation, and admin audit flows are production-ready.
- FCCPC consumer terms need final review for cancellation windows, return/refund remedies, seller disclosures, event disclosures, defective goods, misrepresentation, delivery timing, and complaint escalation.
- Copyright notice/counter-notice, repeat-infringer, evidence retention, and Nigerian Copyright Commission escalation language need counsel sign-off.
- Safety/fraud escalation should be aligned with NPF-NCCC, EFCC/NFIU/provider reporting obligations, and internal incident response runbooks before launch.